fix(test): hermetically exercise auth workflows
This commit is contained in:
@@ -142,9 +142,10 @@ test("OIDC Authorization Code plus PKCE redirects back and maps ordinary and adm
|
||||
expect(stack.lastAuthorization()).toMatchObject({ codeChallengeMethod: "S256", pkceVerified: true });
|
||||
await expectNoWebStorageTokens(page);
|
||||
|
||||
await page.getByRole("button", { name: "Log out", exact: true }).click();
|
||||
await expect(page.getByRole("heading", { name: "Sign in to ThothII" })).toBeVisible();
|
||||
await expect(page.getByRole("button", { name: "Log out", exact: true })).toHaveCount(0);
|
||||
await page.context().clearCookies();
|
||||
stack.setOidcIdentity("admin");
|
||||
await page.goto(stack.publicUrl);
|
||||
await signInWithOidc(page);
|
||||
await expectShell(page);
|
||||
expect((await browserSession(page)).body.roles).toEqual(["admin"]);
|
||||
|
||||
@@ -354,6 +354,7 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
|
||||
const workspaceSecretRoot = join(root, "workspace-secrets");
|
||||
const workspaceRuntimeRoot = join(root, "workspace-runtime");
|
||||
const fixtureSecretRoot = join(root, "fixture-runtime-secrets");
|
||||
const piAgentRoot = join(root, "pi-agent");
|
||||
const providerRoot = join(root, "provider");
|
||||
const authConfigFile = join(root, "auth.yaml");
|
||||
const usersFile = join(root, "users.yaml");
|
||||
@@ -363,8 +364,14 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
|
||||
const authStorageBinary = join(root, "tht-auth-storage");
|
||||
const fixtureDwhPasswordFile = join(fixtureSecretRoot, "fixture-dwh-password");
|
||||
const fixtureDwhCaFile = join(fixtureSecretRoot, "fixture-dwh-ca.pem");
|
||||
for (const path of [stateRoot, registryRoot, workspaceSecretRoot, workspaceRuntimeRoot, fixtureSecretRoot, providerRoot]) secureDirectory(path);
|
||||
for (const path of [stateRoot, registryRoot, workspaceSecretRoot, workspaceRuntimeRoot, fixtureSecretRoot, piAgentRoot, providerRoot]) secureDirectory(path);
|
||||
for (const child of ["sessions", "oidc"]) secureDirectory(join(stateRoot, child));
|
||||
writeSecure(join(piAgentRoot, "settings.json"), JSON.stringify({
|
||||
enabledModels: ["zai/glm-5.2"],
|
||||
}));
|
||||
writeSecure(join(piAgentRoot, "auth.json"), JSON.stringify({
|
||||
zai: { type: "api_key", key: "e2e-model-key-not-a-production-secret" },
|
||||
}));
|
||||
|
||||
const [frontendPort, backendPort] = await Promise.all([freeLoopbackPort(), freeLoopbackPort()]);
|
||||
const publicUrl = `http://127.0.0.1:${frontendPort}`;
|
||||
@@ -494,6 +501,7 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
|
||||
HOST: "127.0.0.1",
|
||||
PORT: String(backendPort),
|
||||
PI_BIN: fakePi,
|
||||
PI_CODING_AGENT_DIR: piAgentRoot,
|
||||
THT_BIN: fakeTht,
|
||||
THT_AUTH_STORAGE_BIN: authStorageBinary,
|
||||
THT_HARNESS_DIR: harnessRoot,
|
||||
|
||||
Reference in New Issue
Block a user